CVE-2024-22091: Mattermost Server
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
Mattermost versions 8.1.x <= 8.1.10, 9.6.x <= 9.6.0, 9.5.x <= 9.5.2 and 8.1.x <= 8.1.11 fail to limit the size of a request path that includes user inputs which allows an attacker to cause excessive resource consumption, possibly leading to a DoS via sending large request paths
Affected products
- Mattermost Mattermost Server: from 8.1.0, before 8.1.12 (fixed in 8.1.12); from 9.5.0, before 9.5.3 (fixed in 9.5.3); from 9.6.0, before 9.6.1 (fixed in 9.6.1)
Published 2024-04-26. Last modified 2026-06-17.